CVE-2013-3712: Critical severity suse studio vulnerability
Published Feb 26, 2014
·Updated
SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vectors.
Affected Software
7 affected components
SUSE Studio Extension for System z=1.3
SUSE Studio onsite=1.3
SUSE Studio onsite=1.3.1
SUSE Studio onsite=1.3.2
SUSE Studio onsite=1.3.3
SUSE Studio onsite=1.3.4
SUSE Studio onsite=1.3.5
Event History
Feb 26, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-3712?
The severity of CVE-2013-3712 is currently unspecified, but it relates to the use of static secret tokens.
2
How do I fix CVE-2013-3712?
To fix CVE-2013-3712, update SUSE Studio Onsite to version 1.3.6 or later, or ensure the use of dynamic secret tokens.
3
What software is affected by CVE-2013-3712?
CVE-2013-3712 affects SUSE Studio Onsite versions 1.3.x before 1.3.6 and SUSE Studio Extension for System z version 1.3.
4
What vulnerabilities does CVE-2013-3712 introduce?
CVE-2013-3712 may lead to potential unauthorized access due to the use of static secret tokens.
5
When was CVE-2013-3712 disclosed?
CVE-2013-3712 was disclosed in 2013 and pertains to vulnerabilities in specific versions of SUSE software.